First published: Wed Jan 11 2023(Updated: )
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Policy Manager for Secure Connect Gateway | >=5.10.00.00<5.14.00.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34440 is classified as a high severity vulnerability due to the potential for unauthorized admin access.
To resolve CVE-2022-34440, update your Dell EMC SCG Policy Manager to version 5.14 or later.
Versions 5.10 to 5.12 of Dell EMC SCG Policy Manager are affected by CVE-2022-34440.
An attacker exploiting CVE-2022-34440 could gain admin privileges through hard-coded cryptographic keys.
Yes, CVE-2022-34440 has been publicly disclosed as part of Dell's security update documentation.